GuidesARCHITECTURE

Free CORS proxy options compared

A free CORS proxy fetches a cross-origin resource server-side and returns it with the headers the browser demands. The options differ sharply in limits, credentials handling, and how much you have to run yourself, and this page compares the ones that are actually alive.

When a free proxy is the right call

A proxy earns its place when the target API is not yours: third-party public endpoints that send no CORS headers, prototypes that need data before infrastructure exists, and client-side apps with no backend of their own. The proxy makes the cross-origin call where no browser policy applies, then re-serves the response with permissive headers.

When you control the target API, skip the intermediary and fix its CORS response headers directly. Anything between your browser and your own server is a needless hop that can read every payload. Managed proxy or your own backend walks through that decision in full.

The options at a glance

Free CORS proxy options compared
OptionHow it worksFree tier limitsCredentials policyBest for
cors.dev (anonymous)Hosted prefix proxy for any public API hostKeyless; fair-use rate limits; 1 MiB, 10 s upstream capNever forwards cookies or AuthorizationKeyless GETs against public APIs
CORS Anywhere (self-host)Your own Node.js proxy serverYour infrastructure; public demo is rate limited and opt-inCookies blocked by default; configurable in codeFull control when you can run a server
corsproxy.ioHosted proxy with API key10,000 requests and 1 GB bandwidth per monthDoes not forward cookies or AuthorizationArbitrary hosts under a monthly free quota
allorigins.winHosted community proxy, no accountNo published limits; availability is intermittentForwards what you send; operator sees trafficQuick one-off fetches, demos
CorsfixHosted proxy with API keyFree trial; paid plans from $5/month, Lite $29/yearAPI key required to call the proxyProduction traffic with paid headroom

cors.dev

cors.dev is a public CORS proxy for browser apps calling public JSON, XML, HTML, CSV and other text APIs. Prefix the target URL and the response comes back with the headers your origin needs. Anonymous use needs no API key, no signup and no registered origin, works from file: pages and curl too, and covers GET and HEAD requests.

cors.dev: prefix the target URL
const response = await fetch(
  'https://proxy.cors.dev/https://api.frankfurter.dev/v1/latest?base=EUR',
);
const rates = await response.json();

Anonymous requests reach any public HTTPS host, GET and HEAD only; hand-picked providers are featured at GET https://cors.dev/api/catalog. Responses are capped at 1 MiB with a 10-second upstream deadline, redirects are followed automatically, and cookies and Authorization headers are never forwarded. Anonymous use has fair-use rate limits with no daily request quota, and an account with Google sign-in adds Connections: saved allowed origins and hosts, publishable project keys, and a per-key activity view. Managed access has separate trial and paid limits.

CORS Anywhere

CORS Anywhere is the open-source Node.js package the hosted-proxy genre grew from, and self-hosting it is the classic cors-anywhere alternative to depending on someone else's server. Your server makes the cross-origin request where no browser check applies, then adds CORS headers to the response. Behavior is configured in code: host whitelists, rate limiting, requireHeader, and redirectSameProtocol. Cookies are not forwarded by default, and the proxy places no restrictions on request methods.

Self-host CORS Anywhere (server.js)
const corsAnywhere = require('cors-anywhere');

const host = '0.0.0.0';
const port = 8080;

corsAnywhere
  .createServer({
    originWhitelist: ['https://your-site.com'],
    requireHeader: ['origin', 'x-requested-with'],
    removeHeaders: ['cookie', 'cookie2'],
  })
  .listen(port, host, () => {
    console.log(`CORS Anywhere running on ${host}:${port}`);
  });

// Clients call: http://localhost:8080/https://api.example.com/data

The public demo at cors-anywhere.herokuapp.com was locked down in February 2021 after sustained abuse. Proxying through it requires visiting the /corsdemo page first and clicking "Request temporary access to the demo server" for temporary opt-in access, and the demo is rate limited to 50 requests per hour and meant for development only.

CORS Anywhere demo syntax (opt-in, rate limited)
// Requires visiting https://cors-anywhere.herokuapp.com/corsdemo first
// and requesting temporary access. Demo limit: 50 requests per hour.
const response = await fetch(
  'https://cors-anywhere.herokuapp.com/https://api.example.com/data',
);

Visit cors.dev vs CORS Anywhere for a side by side breakdown of limits and a before and after migration snippet.

corsproxy.io

corsproxy.io is a hosted proxy that requires a free account and an API key. The target URL goes in the url parameter, percent-encoded, alongside your key.

corsproxy.io: key plus percent-encoded URL
const target = encodeURIComponent('https://api.example.com/data');

const response = await fetch(
  `https://corsproxy.io/?key=YOUR_API_KEY&url=${target}`,
);

// Free tier: 10,000 requests and 1 GB bandwidth per month.

The free tier allows up to 10,000 requests and 1 GB of bandwidth per month. The service is designed not to forward cookies or Authorization headers to target servers.

cors.dev accepts the same ?url= syntax without a key, so moving is a host swap. Review limits and the migration snippet on the cors.dev vs corsproxy.io comparison page.

allorigins.win

allorigins.win is a free community-run proxy with no account and no API key. It exposes two forms: /raw?url= returns the target response body as-is, and /get?url= returns a JSON wrapper with the response in a contents field plus status metadata. Target URLs are percent-encoded.

allorigins.win: raw body or JSON wrapper
// Raw: response body passed through as-is
const raw = await fetch(
  'https://api.allorigins.win/raw?url=https%3A%2F%2Fapi.example.com%2Fdata',
);

// Wrapped: JSON with a contents field plus status metadata
const wrapped = await fetch(
  'https://api.allorigins.win/get?url=https%3A%2F%2Fapi.example.com%2Fdata',
);
const { contents } = await wrapped.json();

There are no published limits, but availability is intermittent: during verification for this page it returned successful responses as well as 520 and 522 origin errors within the same hour. Treat it as a convenience for one-off fetches and demos, not a dependency.

/raw?url= calls work on cors.dev with a host swap; /get callers drop the JSON wrapper. Check cors.dev vs allOrigins for limits and the before and after migration snippet.

Corsfix

Corsfix is a hosted proxy aimed at production use. The target URL goes after https://proxy.corsfix.com/? and requests authenticate with an API key.

Corsfix: target URL after the proxy prefix
const response = await fetch(
  'https://proxy.corsfix.com/?https://api.example.com/data',
  { headers: { Authorization: 'Bearer YOUR_API_KEY' } },
);

// Free trial, then paid plans from $5/month; Lite $29/year for text data.

There is a free trial ("try for $0", no credit card required). Paid plans start at $5 per month (Hobby: unlimited requests, 3 concurrent users, 60 RPM per user, 25 GB bandwidth) and run to $19 per month. A Lite plan at $29 per year covers text data such as JSON APIs and HTML with unlimited requests and bandwidth, 600 RPM shared across your users, and up to 1 MB per response.

Never route secrets through a public proxy

Every proxy operator can observe the traffic that passes through their service, whether that operator is a hosted provider or whoever runs a public CORS Anywhere instance you found in a forum thread. A request through a proxy is a request the operator can read, log, and replay.

Route public data only through any public proxy. API secrets, tokens, session cookies, and private user data belong on infrastructure you control, full stop. The cors.dev free tier rejects requests carrying cookies or an Authorization header. Managed access supports explicit Authorization headers, but never forwards browser cookies or hides private credentials in frontend code.

Get started with cors.dev

For keyless GET and HEAD calls to any public API there is nothing to set up: prefix the URL and fetch. The docs cover request syntax and limits, and the playground lets you test a live URL without writing code.

For write methods and authenticated APIs, managed access adds POST/PUT/PATCH/DELETE on public HTTPS hostnames enabled on your Connection, explicit Authorization and custom API headers, 1 MiB request bodies, and 6 MiB responses within 10 seconds. The trial includes 1,000 requests total over 7 days; Pro costs $5/month for 500,000 requests per monthly billing period. Keep private API credentials on your backend.

Good questions.

Is a free CORS proxy safe to use?

For public data, yes, with the caveat that the operator can observe everything you route through it. Never send secrets, tokens, cookies, or private user data through any public proxy. The cors.dev free tier rejects cookies and Authorization headers; managed access supports explicit Authorization headers but does not make frontend secrets private.

What is the best cors-anywhere alternative?

If you can run a Node.js server, self-hosting CORS Anywhere itself gives you full control with whitelist and rate-limit configuration in code. If you cannot, a hosted proxy like cors.dev (keyless, any public host) or corsproxy.io (API key, monthly free quota) removes the infrastructure burden.

Why does cors-anywhere.herokuapp.com ask me to visit /corsdemo first?

The public demo was locked down in February 2021 after abuse. Visiting /corsdemo and requesting temporary access opts you in for a limited time, and the demo is rate limited to 50 requests per hour and intended for development only. For anything serious, self-host the package.

Are free CORS proxies reliable enough for production?

Community proxies like allorigins.win publish no limits and show intermittent availability, so they fit demos rather than production traffic. Hosted services with defined tiers (cors.dev, corsproxy.io, Corsfix) publish limits you can design around, and paid plans buy headroom when free quotas run out.

Which upstream hosts can the cors.dev free tier reach?

Any public HTTPS host on port 443 for GET and HEAD requests. Private networks, IP literals and credential-bearing URLs are rejected, and every hop, redirects included, must resolve to public addresses before it is fetched. A hand-picked starter list is available at GET https://cors.dev/api/catalog.